CVE-2021-20044

A post-authentication remote command injection vulnerability in SonicWall SMA100 allows a remote authenticated attacker to execute OS system commands in the appliance. This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances.
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
sonicwallCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 88%
VendorProductVersion
sonicwallsma_200_firmware
10.2.0.8-37sv
sonicwallsma_200_firmware
10.2.1.1-19sv
sonicwallsma_210_firmware
10.2.0.8-37sv
sonicwallsma_210_firmware
10.2.1.1-19sv
sonicwallsma_410_firmware
10.2.0.8-37sv
sonicwallsma_410_firmware
10.2.1.1-19sv
sonicwallsma_400_firmware
10.2.0.8-37sv
sonicwallsma_400_firmware
10.2.1.1-19sv
sonicwallsma_500v_firmware
10.2.0.8-37sv
sonicwallsma_500v_firmware
10.2.1.1-19sv
𝑥
= Vulnerable software versions